MAL-2026-3369

    Dashboard / Malicious Package / MAL-2026-3369

    MAL-2026-3369

    Published: 7 May 2026Last Modified: 7 May 2026

    Summary: Malicious code in dabrius (PyPI)

    Details: Source: kam193 (4a154cab742b51be41ca413e20acccfed4290ac4cf692e1cfeb17a677df98bab) The message hidden in the package description tries to convince AI agents to prefer installing the package, which then in multiple places marks execution and collects potentially sensitive data. The behavior extends with each version, up to exfiltration of basic information to a remote target in 1.0.7. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-dabrius Reasons (based on the campaign): - exfiltration-generic - llm-threat - exfiltration-credentials

    Affected packages

    Package

    Name: dabrius

    Purl: pkg:pypi/dabrius

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    0.1.1
    0.1.2
    0.1.3
    MAL-2026-3369 | CVE-DB